public abstract class SignatureSpi extends Object
Signature class, which is used to provide the
 functionality of a digital signature algorithm. Digital signatures are used
 for authentication and integrity assurance of digital data.
.
 All the abstract methods in this class must be implemented by each cryptographic service provider who wishes to supply the implementation of a particular signature algorithm.
Signature| Modifier and Type | Field | Description | 
|---|---|---|
| protected SecureRandom | appRandom | Application-specified source of randomness. | 
| Constructor | Description | 
|---|---|
| SignatureSpi() | 
| Modifier and Type | Method | Description | 
|---|---|---|
| Object | clone() | Returns a clone if the implementation is cloneable. | 
| protected abstract Object | engineGetParameter(String param) | Deprecated.   | 
| protected AlgorithmParameters | engineGetParameters() | This method is overridden by providers to return the parameters
 used with this signature engine. | 
| protected abstract void | engineInitSign(PrivateKey privateKey) | Initializes this signature object with the specified
 private key for signing operations. | 
| protected void | engineInitSign(PrivateKey privateKey,
              SecureRandom random) | Initializes this signature object with the specified
 private key and source of randomness for signing operations. | 
| protected abstract void | engineInitVerify(PublicKey publicKey) | Initializes this signature object with the specified
 public key for verification operations. | 
| protected void | engineSetParameter(AlgorithmParameterSpec params) | This method is overridden by providers to initialize
 this signature engine with the specified parameter set. | 
| protected abstract void | engineSetParameter(String param,
                  Object value) | Deprecated. 
 Replaced by  engineSetParameter. | 
| protected abstract byte[] | engineSign() | Returns the signature bytes of all the data
 updated so far. | 
| protected int | engineSign(byte[] outbuf,
          int offset,
          int len) | Finishes this signature operation and stores the resulting signature
 bytes in the provided buffer  outbuf, starting atoffset. | 
| protected abstract void | engineUpdate(byte b) | Updates the data to be signed or verified
 using the specified byte. | 
| protected abstract void | engineUpdate(byte[] b,
            int off,
            int len) | Updates the data to be signed or verified, using the
 specified array of bytes, starting at the specified offset. | 
| protected void | engineUpdate(ByteBuffer input) | Updates the data to be signed or verified using the specified
 ByteBuffer. | 
| protected abstract boolean | engineVerify(byte[] sigBytes) | Verifies the passed-in signature. | 
| protected boolean | engineVerify(byte[] sigBytes,
            int offset,
            int length) | Verifies the passed-in signature in the specified array
 of bytes, starting at the specified offset. | 
protected SecureRandom appRandom
protected abstract void engineInitVerify(PublicKey publicKey) throws InvalidKeyException
publicKey - the public key of the identity whose signature is
 going to be verified.InvalidKeyException - if the key is improperly
 encoded, parameters are missing, and so on.protected abstract void engineInitSign(PrivateKey privateKey) throws InvalidKeyException
privateKey - the private key of the identity whose signature
 will be generated.InvalidKeyException - if the key is improperly
 encoded, parameters are missing, and so on.protected void engineInitSign(PrivateKey privateKey, SecureRandom random) throws InvalidKeyException
This concrete method has been added to this previously-defined abstract class. (For backwards compatibility, it cannot be abstract.)
privateKey - the private key of the identity whose signature
 will be generated.random - the source of randomnessInvalidKeyException - if the key is improperly
 encoded, parameters are missing, and so on.protected abstract void engineUpdate(byte b)
                              throws SignatureException
b - the byte to use for the update.SignatureException - if the engine is not initialized
 properly.protected abstract void engineUpdate(byte[] b,
                                     int off,
                                     int len)
                              throws SignatureException
b - the array of bytesoff - the offset to start from in the array of byteslen - the number of bytes to use, starting at offsetSignatureException - if the engine is not initialized
 properlyprotected void engineUpdate(ByteBuffer input)
data.remaining() bytes
 starting at at data.position().
 Upon return, the buffer's position will be equal to its limit;
 its limit will not have changed.input - the ByteBufferprotected abstract byte[] engineSign()
                              throws SignatureException
SignatureException - if the engine is not
 initialized properly or if this signature algorithm is unable to
 process the input data provided.protected int engineSign(byte[] outbuf,
                         int offset,
                         int len)
                  throws SignatureException
outbuf, starting at
 offset.
 The format of the signature depends on the underlying
 signature scheme.
 The signature implementation is reset to its initial state
 (the state it was in after a call to one of the
 engineInitSign methods)
 and can be reused to generate further signatures with the same private
 key.
 This method should be abstract, but we leave it concrete for
 binary compatibility.  Knowledgeable providers should override this
 method.
outbuf - buffer for the signature result.offset - offset into outbuf where the signature is
 stored.len - number of bytes within outbuf allotted for the
 signature.
 Both this default implementation and the SUN provider do not
 return partial digests. If the value of this parameter is less
 than the actual signature length, this method will throw a
 SignatureException.
 This parameter is ignored if its value is greater than or equal to
 the actual signature length.outbufSignatureException - if the engine is not
 initialized properly, if this signature algorithm is unable to
 process the input data provided, or if len is less
 than the actual signature length.protected abstract boolean engineVerify(byte[] sigBytes)
                                 throws SignatureException
sigBytes - the signature bytes to be verified.SignatureException - if the engine is not
 initialized properly, the passed-in signature is improperly
 encoded or of the wrong type, if this signature algorithm is unable to
 process the input data provided, etc.protected boolean engineVerify(byte[] sigBytes,
                               int offset,
                               int length)
                        throws SignatureException
Note: Subclasses should overwrite the default implementation.
sigBytes - the signature bytes to be verified.offset - the offset to start from in the array of bytes.length - the number of bytes to use, starting at offset.SignatureException - if the engine is not
 initialized properly, the passed-in signature is improperly
 encoded or of the wrong type, if this signature algorithm is unable to
 process the input data provided, etc.@Deprecated protected abstract void engineSetParameter(String param, Object value) throws InvalidParameterException
engineSetParameter.param - the string identifier of the parameter.value - the parameter value.InvalidParameterException - if param is an
 invalid parameter for this signature algorithm engine,
 the parameter is already set
 and cannot be set again, a security exception occurs, and so on.protected void engineSetParameter(AlgorithmParameterSpec params) throws InvalidAlgorithmParameterException
This method is overridden by providers to initialize this signature engine with the specified parameter set.
params - the parametersUnsupportedOperationException - if this method is not
 overridden by a providerInvalidAlgorithmParameterException - if this method is
 overridden by a provider and the given parameters
 are inappropriate for this signature engineprotected AlgorithmParameters engineGetParameters()
This method is overridden by providers to return the parameters used with this signature engine.
 If this signature engine has been previously initialized with
 parameters (by calling the engineSetParameter method), this
 method returns the same parameters. If this signature engine has not been
 initialized with parameters, this method may return a combination of
 default and randomly generated parameter values if the underlying
 signature implementation supports it and can successfully generate
 them. Otherwise, null is returned.
nullUnsupportedOperationException - if this method is
 not overridden by a provider@Deprecated protected abstract Object engineGetParameter(String param) throws InvalidParameterException
param - the string name of the parameter.null if
 there is none.InvalidParameterException - if param is an
 invalid parameter for this engine, or another exception occurs while
 trying to get this parameter.public Object clone() throws CloneNotSupportedException
clone in class ObjectCloneNotSupportedException - if this is called
 on an implementation that does not support Cloneable.Cloneable Submit a bug or feature 
For further API reference and developer documentation, see Java SE Documentation. That documentation contains more detailed, developer-targeted descriptions, with conceptual overviews, definitions of terms, workarounds, and working code examples.
 Copyright © 1993, 2025, Oracle and/or its affiliates.  All rights reserved. Use is subject to license terms. Also see the documentation redistribution policy.